stellular-truffle-25b117[.]netlify[.]app
“DocuSign - Download to View Document”
stellular-truffle-25b117.netlify.app — Contenuto non disponibile. Simulazione del marchio: Docusign; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 21/92 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Ermes); URLQuery 4 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Registrar: Netlify.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Threat intelligence identifies stellular-truffle-25b117.netlify.app as an active credential-harvesting domain posing as a legitimate login portal. This domain mimics a branded authentication page to trick users into surrendering credentials, which are then exfiltrated to attacker-controlled servers. Analysis confirms the infrastructure is hosted on IP 35.157.26.135 and leverages a DigiCert SSL certificate to appear legitimate and evade browser warnings. The domain was registered via Netlify and has already triggered detections from 19 of 95 VirusTotal security vendors, indicating elevated risk and active abuse in phishing campaigns.
This domain was flagged by 19 out of 95 VirusTotal security vendors, confirming widespread recognition of its malicious intent. It resolves to IP address 35.157.26.135 and is registered through Netlify, a platform often abused by threat actors to host convincing phishing pages with minimal friction. The presence of a valid DigiCert SSL certificate further enhances its credibility, increasing the likelihood of successful deception. The campaign is currently active and represents a credible threat to users who may encounter it through email, social media, or malicious advertisements.
If you visited stellular-truffle-25b117.netlify.app, assume your credentials were compromised and immediately change passwords for any accounts entered. Enable multi-factor authentication on all related accounts and review recent login activity for anomalies. Report the domain to your security team or ISP and avoid any further interaction. Consider using a password manager to detect and prevent reuse of credentials on fraudulent sites. Monitor financial accounts and enable transaction alerts if sensitive data was entered. Stay alert for follow-on phishing attempts leveraging this breach.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | stellular-truffle-25b117.netlify.app/ |
malware | Detects file containing Telegram Bot API |
| Cloudflare DNS | stellular-truffle-25b117.netlify.app |
malicious | Sinkholed |
| OpenDNS | stellular-truffle-25b117.netlify.app |
phishing | Phishing Block |
| DNS4EU | stellular-truffle-25b117.netlify.app |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 4 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com Confidenza al 100%LiveChat is an online customer service software with online chat, help desk software, and web analytics capabilities.
www.livechat.com Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of stellular-truffle-25b117.netlify.app · checked May 14, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo